CVE-2008-2811Mozilla Firefox vulnerability

CWE-3996 documents5 sources
Severity
10.0CRITICALNVD
EPSS
24.2%
top 3.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 7
Latest updateMay 1

Description

The block reflow implementation in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an image whose display requires more pixels than nscoord_MAX, related to nsBlockFrame::DrainOverflowLines.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages3 packages

NVDmozilla/firefox2.0.0.14+14
NVDmozilla/seamonkey1.1.9+8
NVDmozilla/thunderbird2.0.0.14+12

🔴Vulnerability Details

1
GHSA
GHSA-f329-4wvc-4h42: The block reflow implementation in Mozilla Firefox before 22022-05-01

📋Vendor Advisories

3
Ubuntu
Thunderbird vulnerabilities2008-07-25
Red Hat
Firefox block reflow flaw2008-07-02
Ubuntu
Firefox vulnerabilities2008-07-02

💬Community

1
Bugzilla
CVE-2008-2811 Firefox block reflow flaw2008-06-26
CVE-2008-2811 — Mozilla Firefox vulnerability | cvebase